PT-2026-29864 · Openproject · Openproject
Ochk0
·
Published
2026-04-02
·
Updated
2026-04-03
·
CVE-2026-34717
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenProject versions prior to 17.2.3
Description
OpenProject, a web-based project management software, has an issue where user input is directly embedded into SQL WHERE clauses without proper parameterization. This occurs due to the =n operator in modules/reporting/lib/report/operator.rb:177. This could allow for SQL injection. The issue affects authenticated users and could potentially grant them database access.
Recommendations
Update to version 17.2.3 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openproject